PT-2024-4310 · Ibm · Ibm Db2+1

Published

2024-06-12

·

Updated

2024-08-07

·

CVE-2024-28762

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) versions 10.5, 11.1, and 11.5
Description The issue is related to the management of database systems, specifically IBM DB2 and IBM DB2 Connect Server, which are vulnerable to denial of service attacks. This can be achieved by exploiting the unlimited allocation of resources, allowing a remote attacker to cause a denial of service using specially crafted queries under certain conditions.
Recommendations For versions 10.5, 11.1, and 11.5, consider restricting access to the database system to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling the execution of specially crafted queries until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2024-04798
CVE-2024-28762

Affected Products

Db2 Connect Server
Ibm Db2